Certified Information Privacy Professional CIPPE · Free Practice Question Easy
Question 14
What is true about a company that was exposed to a ransomware attack, but the data that was exposed is encrypted?
-
A
There was no data breach
-
B
The company experienced a personal data breach
-
C
The company must notify the DPA
-
D
The company must notify the affected customers
Reveal correct answer
Correct answer: B
Explanation
This was a data breach as the hacker was able to access encrypted personal data and a data breach is defined as an unauthorized or accidental disclosure of or access to personal data.
In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.
When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
In this case, as the data that was exposed was encrypted the breach is unlikely to result n a high risk to the rights and freedoms of natural persons. Therefore neither the DPA nor customers should be notified.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
